26#include "dbus-credentials.h"
27#include "dbus-internals.h"
57 BusPDPLinuxID* credential_parsecid;
60 char *linux_security_label;
62 dbus_int32_t adt_audit_data_size;
88 creds->unix_gids =
NULL;
89 creds->n_unix_gids = 0;
92 creds->credential_parsecid =
NULL;
94 creds->windows_sid =
NULL;
95 creds->linux_security_label =
NULL;
96 creds->adt_audit_data =
NULL;
97 creds->adt_audit_data_size = 0;
133 credentials->refcount += 1;
146 credentials->refcount -= 1;
147 if (credentials->refcount == 0)
151 dbus_free (credentials->linux_security_label);
154 if (credentials->credential_parsecid)
dbus_free(credentials->credential_parsecid);
155 credentials->credential_parsecid=
NULL;
174 _dbus_verbose(
"***** Add PID to credentials (%p)! %ld\n",credentials,pid);
176 credentials->pid = pid;
191 credentials->unix_uid = uid;
197cmp_gidp (
const void *a_,
const void *b_)
225 qsort (gids, n_gids,
sizeof (
dbus_gid_t), cmp_gidp);
228 credentials->unix_gids = gids;
229 credentials->n_unix_gids = n_gids;
245 *gids = credentials->unix_gids;
248 *n_gids = credentials->n_unix_gids;
250 return (credentials->unix_gids !=
NULL);
262 const char *windows_sid)
271 credentials->windows_sid = copy;
294 dbus_free (credentials->linux_security_label);
295 credentials->linux_security_label = copy;
319 credentials->adt_audit_data = copy;
320 credentials->adt_audit_data_size = size;
334 DBusCredentialType type)
338 case DBUS_CREDENTIAL_UNIX_PROCESS_ID:
340 case DBUS_CREDENTIAL_UNIX_USER_ID:
342 case DBUS_CREDENTIAL_UNIX_GROUP_IDS:
343 return credentials->unix_gids !=
NULL;
344 case DBUS_CREDENTIAL_WINDOWS_SID:
345 return credentials->windows_sid !=
NULL;
346 case DBUS_CREDENTIAL_LINUX_SECURITY_LABEL:
347 return credentials->linux_security_label !=
NULL;
348 case DBUS_CREDENTIAL_ADT_AUDIT_DATA_ID:
349 return credentials->adt_audit_data !=
NULL;
351 case DBUS_CREDENTIAL_UNIX_PARSEC:
352 return credentials->credential_parsecid !=
NULL;
370 return credentials->pid;
383 return credentials->unix_uid;
396 return credentials->windows_sid;
409 return credentials->linux_security_label;
422 return credentials->adt_audit_data;
435 return credentials->adt_audit_data_size;
452 possible_subset->pid == credentials->pid) &&
454 (possible_subset->credential_parsecid ==
NULL ||
455 (credentials->credential_parsecid && possible_subset->credential_parsecid &&
456 credentials->credential_parsecid->sz_pdplinux_context==possible_subset->credential_parsecid->sz_pdplinux_context &&
457 (0==memcmp(possible_subset->credential_parsecid,credentials->credential_parsecid,
458 sizeof(*(credentials->credential_parsecid))+credentials->credential_parsecid->sz_pdplinux_context))) ) &&
461 possible_subset->unix_uid == credentials->unix_uid) &&
462 (possible_subset->unix_gids ==
NULL ||
463 (possible_subset->n_unix_gids == credentials->n_unix_gids &&
464 memcmp (possible_subset->unix_gids, credentials->unix_gids,
465 sizeof (
dbus_gid_t) * credentials->n_unix_gids) == 0)) &&
466 (possible_subset->windows_sid ==
NULL ||
467 (credentials->windows_sid && strcmp (possible_subset->windows_sid,
468 credentials->windows_sid) == 0)) &&
469 (possible_subset->linux_security_label ==
NULL ||
470 (credentials->linux_security_label !=
NULL &&
471 strcmp (possible_subset->linux_security_label,
472 credentials->linux_security_label) == 0)) &&
473 (possible_subset->adt_audit_data ==
NULL ||
474 (credentials->adt_audit_data && memcmp (possible_subset->adt_audit_data,
475 credentials->adt_audit_data,
476 credentials->adt_audit_data_size) == 0));
491 (credentials->credential_parsecid==
NULL) &&
494 credentials->unix_gids ==
NULL &&
495 credentials->n_unix_gids == 0 &&
496 credentials->windows_sid ==
NULL &&
497 credentials->linux_security_label ==
NULL &&
498 credentials->adt_audit_data ==
NULL;
512 credentials->windows_sid ==
NULL;
529 DBUS_CREDENTIAL_UNIX_PROCESS_ID,
530 other_credentials) &&
532 DBUS_CREDENTIAL_UNIX_USER_ID,
533 other_credentials) &&
535 DBUS_CREDENTIAL_UNIX_GROUP_IDS,
536 other_credentials) &&
538 DBUS_CREDENTIAL_ADT_AUDIT_DATA_ID,
539 other_credentials) &&
541 DBUS_CREDENTIAL_LINUX_SECURITY_LABEL,
542 other_credentials) &&
544 DBUS_CREDENTIAL_WINDOWS_SID,
548 DBUS_CREDENTIAL_UNIX_PARSEC,
570 DBusCredentialType which,
573 if (which == DBUS_CREDENTIAL_UNIX_PROCESS_ID &&
579 else if (which == DBUS_CREDENTIAL_UNIX_USER_ID &&
585 else if (which == DBUS_CREDENTIAL_UNIX_GROUP_IDS &&
586 other_credentials->unix_gids !=
NULL)
595 memcpy (gids, other_credentials->unix_gids,
596 sizeof (
dbus_gid_t) * other_credentials->n_unix_gids);
599 other_credentials->n_unix_gids);
601 else if (which == DBUS_CREDENTIAL_WINDOWS_SID &&
602 other_credentials->windows_sid !=
NULL)
607 else if (which == DBUS_CREDENTIAL_LINUX_SECURITY_LABEL &&
608 other_credentials->linux_security_label !=
NULL)
611 other_credentials->linux_security_label))
614 else if (which == DBUS_CREDENTIAL_ADT_AUDIT_DATA_ID &&
615 other_credentials->adt_audit_data !=
NULL)
621 else if (which == DBUS_CREDENTIAL_UNIX_PARSEC){
623 _dbus_verbose(
"***** Asked to add credential DBUS_CREDENTIAL_UNIX_PARSEC (%d))\n", which);
625 if (other_credentials->credential_parsecid !=
NULL) {
626 if (!_dbus_credentials_pdplinux_add_unix_parsec (credentials, other_credentials->credential_parsecid)){
627 _dbus_verbose(
"Return FAILED (can't set credentials to this one from other_credentials)\n");
631 _dbus_verbose(
"Return OK (credentials successful copied to this one from other_credentials)\n");
635 _dbus_verbose(
"Return OK (but other_cred not set pid=%ld, uid=%lu). So do not add, pdp_credential=%p\n",
636 other_credentials->pid,
637 other_credentials->unix_uid,
638 credentials->credential_parsecid);
656 if (credentials->credential_parsecid)
dbus_free(credentials->credential_parsecid);
657 credentials->credential_parsecid=
NULL;
662 credentials->unix_gids =
NULL;
663 credentials->n_unix_gids = 0;
665 credentials->windows_sid =
NULL;
666 dbus_free (credentials->linux_security_label);
667 credentials->linux_security_label =
NULL;
669 credentials->adt_audit_data =
NULL;
670 credentials->adt_audit_data_size = 0;
715 return credentials->unix_uid == other_credentials->unix_uid &&
716 ((!(credentials->windows_sid || other_credentials->windows_sid)) ||
717 (credentials->windows_sid && other_credentials->windows_sid &&
718 strcmp (credentials->windows_sid, other_credentials->windows_sid) == 0));
749 if (credentials->unix_gids !=
NULL)
753 for (i = 0; i < credentials->n_unix_gids; i++)
757 credentials->unix_gids[i]))
764 if (credentials->windows_sid !=
NULL)
771 if (credentials->linux_security_label !=
NULL)
775 credentials->linux_security_label))
780 if (credentials->credential_parsecid !=
NULL)
782 char* pdplinux_context_string=
NULL;
784 if (_dbus_pdplinux_context_to_name(credentials->credential_parsecid,&pdplinux_context_string)){
788 pdplinux_context_string)){
794 if (pdplinux_context_string)
dbus_free(pdplinux_context_string);
810_dbus_credentials_pdplinux_get_unix_parsec (
DBusCredentials *credentials, BusPDPLinuxID** pparsecid)
812 *pparsecid=credentials->credential_parsecid;
817_dbus_credentials_pdplinux_add_unix_parsec (
DBusCredentials *credentials,
818 BusPDPLinuxID* parsecid)
820 if (!parsecid)
return FALSE;
821 if (!credentials)
return FALSE;
823 if (credentials->credential_parsecid)
dbus_free(credentials->credential_parsecid);
824 credentials->credential_parsecid=
NULL;
827 sizeof(*(parsecid))+parsecid->sz_pdplinux_context);
829 if (credentials->credential_parsecid){
830 memcpy(credentials->credential_parsecid,parsecid,
831 sizeof(*(parsecid))+parsecid->sz_pdplinux_context);
834 _dbus_verbose(
"No memory!\n");
void _dbus_credentials_ref(DBusCredentials *credentials)
Increment refcount on credentials.
dbus_bool_t _dbus_credentials_include(DBusCredentials *credentials, DBusCredentialType type)
Checks whether the given credential is present.
dbus_bool_t _dbus_credentials_are_superset(DBusCredentials *credentials, DBusCredentials *possible_subset)
Checks whether the first credentials object contains all the credentials found in the second credenti...
dbus_bool_t _dbus_credentials_same_user(DBusCredentials *credentials, DBusCredentials *other_credentials)
Check whether the user-identifying credentials in two credentials objects are identical.
void _dbus_credentials_clear(DBusCredentials *credentials)
Clear all credentials in the object.
dbus_uid_t _dbus_credentials_get_unix_uid(DBusCredentials *credentials)
Gets the UNIX user ID in the credentials, or DBUS_UID_UNSET if the credentials object doesn't contain...
DBusCredentials * _dbus_credentials_copy(DBusCredentials *credentials)
Copy a credentials object.
DBusCredentials * _dbus_credentials_new_from_current_process(void)
Creates a new object with the most important credentials (user ID and process ID) from the current pr...
dbus_bool_t _dbus_credentials_to_string_append(DBusCredentials *credentials, DBusString *string)
Convert the credentials in this object to a human-readable string format, and append to the given str...
DBusCredentials * _dbus_credentials_new(void)
Creates a new credentials object.
void * _dbus_credentials_get_adt_audit_data(DBusCredentials *credentials)
Gets the ADT audit data in the credentials, or NULL if the credentials object doesn't contain ADT aud...
dbus_bool_t _dbus_credentials_add_linux_security_label(DBusCredentials *credentials, const char *label)
Add a Linux security label, as used by LSMs such as SELinux, Smack and AppArmor, to the credentials.
dbus_bool_t _dbus_credentials_add_credentials(DBusCredentials *credentials, DBusCredentials *other_credentials)
Merge all credentials found in the second object into the first object, overwriting the first object ...
const char * _dbus_credentials_get_linux_security_label(DBusCredentials *credentials)
Gets the Linux security label (as used by LSMs) from the credentials, or NULL if the credentials obje...
void _dbus_credentials_take_unix_gids(DBusCredentials *credentials, dbus_gid_t *gids, size_t n_gids)
Add UNIX group IDs to the credentials, replacing any group IDs that might already have been present.
void _dbus_credentials_unref(DBusCredentials *credentials)
Decrement refcount on credentials.
dbus_bool_t _dbus_credentials_get_unix_gids(DBusCredentials *credentials, const dbus_gid_t **gids, size_t *n_gids)
Get the Unix group IDs.
dbus_bool_t _dbus_credentials_are_empty(DBusCredentials *credentials)
Checks whether a credentials object contains anything.
dbus_bool_t _dbus_credentials_add_unix_uid(DBusCredentials *credentials, dbus_uid_t uid)
Add a UNIX user ID to the credentials.
dbus_bool_t _dbus_credentials_add_windows_sid(DBusCredentials *credentials, const char *windows_sid)
Add a Windows user SID to the credentials.
dbus_bool_t _dbus_credentials_add_pid(DBusCredentials *credentials, dbus_pid_t pid)
Add a UNIX process ID to the credentials.
dbus_pid_t _dbus_credentials_get_pid(DBusCredentials *credentials)
Gets the UNIX process ID in the credentials, or DBUS_PID_UNSET if the credentials object doesn't cont...
dbus_bool_t _dbus_credentials_add_adt_audit_data(DBusCredentials *credentials, void *audit_data, dbus_int32_t size)
Add ADT audit data to the credentials.
dbus_int32_t _dbus_credentials_get_adt_audit_data_size(DBusCredentials *credentials)
Gets the ADT audit data size in the credentials, or 0 if the credentials object doesn't contain ADT a...
const char * _dbus_credentials_get_windows_sid(DBusCredentials *credentials)
Gets the Windows user SID in the credentials, or NULL if the credentials object doesn't contain a Win...
dbus_bool_t _dbus_credentials_add_credential(DBusCredentials *credentials, DBusCredentialType which, DBusCredentials *other_credentials)
Merge the given credential found in the second object into the first object, overwriting the first ob...
dbus_bool_t _dbus_credentials_are_anonymous(DBusCredentials *credentials)
Checks whether a credentials object contains a user identity.
#define _dbus_assert_not_reached(explanation)
Aborts with an error message if called.
#define _dbus_assert(condition)
Aborts with an error message if the condition is false.
char * _dbus_strdup(const char *str)
Duplicates a string.
void * _dbus_memdup(const void *mem, size_t n_bytes)
Duplicates a block of memory.
#define NULL
A null pointer, defined appropriately for C or C++.
#define TRUE
Expands to "1".
#define FALSE
Expands to "0".
void dbus_free(void *memory)
Frees a block of memory previously allocated by dbus_malloc() or dbus_malloc0().
#define dbus_new(type, count)
Safe macro for using dbus_malloc().
void * dbus_malloc0(size_t bytes)
Allocates the given number of bytes, as with standard malloc(), but all bytes are initialized to zero...
dbus_bool_t _dbus_string_append_printf(DBusString *str, const char *format,...)
Appends a printf-style formatted string to the DBusString.
unsigned long dbus_uid_t
A user ID.
unsigned long dbus_pid_t
A process ID.
unsigned long dbus_gid_t
A group ID.
#define DBUS_UID_UNSET
an invalid UID used to represent an uninitialized dbus_uid_t field
#define DBUS_PID_UNSET
an invalid PID used to represent an uninitialized dbus_pid_t field
dbus_bool_t _dbus_credentials_add_from_current_process(DBusCredentials *credentials)
Adds the most important credentials of the current process (the uid and pid) to the passed-in credent...
#define DBUS_GID_FORMAT
an appropriate printf format for dbus_gid_t
#define DBUS_UID_FORMAT
an appropriate printf format for dbus_uid_t
#define DBUS_PID_FORMAT
an appropriate printf format for dbus_pid_t
dbus_uint32_t dbus_bool_t
A boolean, valid values are TRUE and FALSE.